Security News > 2020 > May > Vulnerabilities in 'Page Builder' Plugin Expose 1 Million WordPress Websites

Vulnerabilities in 'Page Builder' Plugin Expose 1 Million WordPress Websites
2020-05-12 16:01

Two high-severity vulnerabilities addressed recently in SiteOrigin's Page Builder WordPress plugin could allow an attacker to execute code in a website administrator's browser.

A page creation plugin, Page Builder by SiteOrigin helps users create column-based content that can adapt to mobile devices, and also provides them with support for the most common widgets.

The plugin has more than 1 million active installations.

While there are checks in place to verify that the user is in the live editor, and that the user is allowed to edit posts, the plugin did not include a nonce protection to verify whether attempts to render content in the live editor came from legitimate sources or not.

Both vulnerabilities were addressed with the release of Page Builder by SiteOrigin version 2.10.16.


News URL

http://feedproxy.google.com/~r/Securityweek/~3/oTLrgWYS2X0/vulnerabilities-page-builder-plugin-expose-1-million-wordpress-websites

Related vendor

VENDOR LAST 12M #/PRODUCTS LOW MEDIUM HIGH CRITICAL TOTAL VULNS
Wordpress 7 2 95 44 18 159
Plugin 2 0 13 1 0 14